Hyperlink NFT Extension
gilmlbeecofjmogfkaocnjmbiblmifad
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Extension stale ~25 months; no updates since June 2023.
- Developer uses free Gmail address with no verifiable business identity.
- Content script injected into all twitter.com pages broadens attack surface for any future compromise.
- Two innerHTML DOM-XSS sinks present; CSP does not include trusted-types or nonce protection.
Evidence
- privacy_policy_generic_google store Privacy URL points to myaccount.google.com/privacypolicy — generic Google policy, not scoped to this extension. scope_extension=false, third_party_sharing=true.
- developer_free_webmail store Developer email kaikaikangkang@gmail.com — free webmail, no verifiable business domain.
- stale_extension store Last updated June 8 2023; ~25 months since update. MV3 but no active maintenance signals.
- content_script_twitter manifest content_scripts injected on *://*.twitter.com/* — broad social platform reach for 1000-install NFT extension.
- dom_xss_sinks crx Two innerHTML-from-variable findings: fontawesome.min.js and assets/index.e60fe6e6.js. CSP present but no trusted-types.
- react_16_bundled crx React 16.13.1 bundled — below 16.14 patching threshold; no CVEs flagged in cve_findings_raw.
- js_external_hosts crx JS contacts app.parami.io and reactjs.org; both single-country US, no bad-host hits.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false, no recognized org. Reputation floor applies.
Permissions Breakdown
- storage low Stores local extension state; limited blast radius.
- tabs medium Can read tab URLs and titles; moderate info-disclosure risk.
- content_scripts(*://*.twitter.com/*) medium Injects JS into all Twitter pages; can read/mutate page content.
- content_scripts(https://app.parami.io/*) low Scoped to developer's own domain; narrow surface.
Pillar Scores
Permissions2.30
Reputation7.00
Network0.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 06:07
Listing SHA
1c69deb2f72c…
Force block
— not fired
Score recovered
no
Elapsed
25.8s